TLS handshake reset on custom domain

.netlify.app works, cert shows valid

Site: digitaldowntownmain.netlify.app Custom domains: digitaldowntownmain.com, www.digitaldowntownmain.com DNS: Netlify DNS (nameservers dns1-4.p04.nsone.net)

My site serves correctly at digitaldowntownmain.netlify.app (HTTP 200), but both custom domains fail with a TLS handshake reset. DNS resolves to edge IPs 18.208.88.157 and 98.84.224.111 (same IPs the .netlify.app hostname uses), TCP connects on :443, then the handshake is reset before completion.

curl -v https://www.digitaldowntownmain.com

  • Trying 18.208.88.157:443…
  • ALPN: curl offers http/1.1
  • Recv failure: Connection was reset
  • schannel: failed to receive handshake, SSL/TLS connection failed
    curl: (35) Recv failure: Connection was reset

Certificate status: Let’s Encrypt, shows as valid in dashboard, covers digitaldowntownmain.com and *.digitaldowntownmain.com, created Apr 8, auto-renews Jul 7.

Domain management: digitaldowntownmain.com set as primary, www.digitaldowntownmain.com set to redirect to primary. Both show Netlify DNS with green checkmarks.

DNS: No CAA records, no AAAA records. NS records correctly delegated to Netlify DNS.

Already tried:

  • Renew certificate (no change)

  • Verified domain aliases and primary configuration

  • Confirmed no conflicting DNS records

Issue has been intermittent over the past couple of days — site comes up, goes down, comes back. Looks like an edge binding that’s out of sync with the dashboard state. Can an engineer take a look?